Andrew Mercer
on this page

    John the Ripper tests password hashes against wordlists and rules. It is used to audit your own systems for weak passwords (for example, finding guessable passwords in a directory export before an attacker does).

    Only run it against hashes you are authorised to test.

    # Combine passwd and shadow (root) into a single file John understands
    sudo unshadow /etc/passwd /etc/shadow > hashes.txt
    
    john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt      # dictionary attack
    john --show hashes.txt                                           # display cracked passwords
    john --list=formats | tr ',' '\n' | head                        # supported hash types
    

    Passwords that fall to a dictionary attack in seconds should be reset, and the underlying cause fixed (length and passphrase policy, multi-factor authentication, or a password manager such as pass). Delete the hash files when you are done.